advertisement
advertisement

This is page 4 of:

Target, Starbucks Suffer Mobile Gift Card Security Hole

May 13th, 2010

How can gift cards be made more secure? Several ways.

  • Get ‘Em Out Of Sight.
    As a short-term measure until more robust security measures are fully deployed, the gift cards can be placed behind the counter, alongside cigarettes, adult-themed items and restricted types of over-the-counter medicines. Because these fraud tactics required close examination of the items, this approach would slow down the assaults from customers.

    Then again, most fraud attempts are inside jobs. As such, the “shove ’em behind a counter” tactic won’t do much to deter employee fraud, which could mean that this plan won’t make as large a dent as it could. Still, any reduction is helpful.

  • Use Dummy Cards.
    Speaking of the “Get ‘Em Out Of Sight” suggestion, there’s a non-trivial concern about out-of-sight out-of-mind. There’s a reason gift cards have been prominently displayed and it’s because marketing wants them to be as convenient for consumers to grab as possible. But that goal can still be achieved by replacing the real cards with cheap dummy cards.

    Editor’s Note:

  • Page 1 of this Special Report covers The Overview And Impact of this security hole
  • Page 2 covers Technical Specs
  • Page 3 covers the Social Engineering Specs
  • Page 4 covers Ways To Fix The Hole

    When someone brings one up to the cashier, the associate pulls out a real card from a drawer. This approach is not that different from what video rental stores (anyone remember those?) used to do, with empty video cases on the shelf and the real videos to be retrieved by a store associate as they’re being paid for.

  • PINs and Tokens.
    This point gets into the area of actually improving card security, which would require POS and app changes. Forcing the customer to type in a PIN when the card is loaded with value is not especially onerous, nor is seeking that PIN for using the card.

    Tokenization is a behind-the-scenes approach to secure the mobile process. It’s not clear if it would be needed, but some forms of tokenization might take some of the load off of retailers. Then again, a strict PIN approach might be sufficient.

  • Better Training, At The Cost Of Speed.
    This topic gets into one of the oldest Loss Prevention debates. Should checkout speed (how many customers can be processed in any one-hour period) trump security?

    Scams using fake barcode labels on products have often been quite successful, relying on the fact that cashiers wouldn’t look up long enough to notice that a product scanning as a watermelon was actually a flat-screen television. When was the last time a chain pushed associates to take the time to look at and compare credit card signatures with the customer’s signature? (It sort of makes signing the credit card a nostalgic act.)

    For those retailers willing to sacrifice speed for fraud reduction, these scams are not that difficult to detect. Look at the phone. Is that your chain’s app? Ask the customer to click on an icon. With an iPhone, a good technique is to simply ask for the phone to be tilted. If it’s just a picture, it will reorient and shrink, while the actual app would act differently.

    Liability concerns notwithstanding, asking the cashier to briefly hold the phone to scan the barcode—while moving the image on the screen—wouldn’t be out-of-line. Still, these are time-consuming steps. If mobile apps become as popular as many predict, these verification tactics could become untenable. Then again, so could the fraud losses.


  • advertisement

    3 Comments | Read Target, Starbucks Suffer Mobile Gift Card Security Hole

    1. Mike Says:

      How is this any more of a risk than regular gift cards today? Gift cards don’t have a second validation point. If someone gets access to a gift card, the same information is available and either the card can be used physically, or in many cases online.

      It seems to me that all of the folks in this article are exagerating the point to gain attention for themselves.

      I’d rather someone explain to me why I would pull out my phone, select an app (typically buried 3 pages back)then navigate to the right card, then select pay, show the bar code to the associate, they scan it 4 times, give up and then type the PAN in manually… instead of just pulling out my card from my wallet and swiping.

      Mobile wallets are a long way away. But a retina scan being required when I get my Americano isn’t required.

    2. Evan Schuman Says:

      Mike asked, “How is this any more of a risk than regular gift cards today?” It’s a fair question. The answer is in the ease of the fraud. It’s an order of magnitude more labor-intensive to create a duplicate bogus gift card that looks convincing. The magstripe would likely need to be forged as well. Not that it can’t be done, of course, as there is a lively business making and selling cloned cards with stolen information. But what makes these mobile holes so problematic is that they are so incredibly easy and inexpensive (free, really) to use. A security hole is only dangerous to the degree that thieves are going to try and leverage it. The mobile offerings seemed so much easier that it struck us as a much more ominous threat.

    3. Rocky Rosenberg Says:

      Simple solution? Cover the gift card number with a scratch off coating (like the PIN). Educate clerks not to activate gift cards when the scratch off coating has been tampered with.

    Newsletters

    StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!
    advertisement

    Most Recent Comments

    Why Did Gonzales Hackers Like European Cards So Much Better?

    I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
    Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
    A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
    The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
    @David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

    StorefrontBacktalk
    Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.